Posts

Showing posts with the label html injection

Hack the Box - Brainfuck - Walkthrough

Image
Introduction Today we're going to be doing a pentest walkthrough of the Brainfuck machine hosted at https://hackthebox.eu . For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the Brainfuck machine as the victim system.  After connecting to the Hack the Box network via VPN, we see that our target is located at 10.129.96.96. Scanning and Enumeration We'll start by scanning for open ports with Nmap: sudo nmap -T4 -p- 10.129.96.96 Now we'll do another Nmap scan, this time specifying the ports and picking up service names and version numbers: sudo nmap -T4 -p22,25,110,143,443 10.129.96.96 Seeing that there's an HTTPS service open, we'll use Nmap scripts to enumerate the SSL certificate: nmap --script=ssl* -p443 10.129.96.96 We see three URLs associated with the certificate, so we'll add those URLs to our /etc/hosts file so that those addresses resolve properly in our web browser: sudo gedit /etc/hosts Now we can navigate to ...